Security
Security, in plain English
Vassal Agent runs on your own computer, with your own AI plan, and asks before it sends, pays or deletes anything. Your sign-ins stay locked on that computer. What your team shares, and what syncs between your computers, is encrypted before it leaves, with keys we never have.
It runs on your computer
Vassal Agent is a desktop app for Mac and Windows with its own browser inside. The pages it opens, your cookies and sign-ins, your chats with your AI, your workflows and the log of every action it takes are kept on your computer. We don't receive them.
It has no analytics or ad trackers. Crash reports are off unless you turn them on, and never include your pages or what you type.
Your AI runs on your own plan
You connect the AI you already pay for: Claude, ChatGPT (through Codex) or Gemini. It runs under your own account with that provider. The page content your AI reads to do a job goes to your provider, never to us, and we never pay for it or receive it.
Sign-ins stay locked on the computer
- Saved passwords are locked by your computer itself: the macOS Keychain on a Mac, and Windows' own encryption for your user account (DPAPI) on a PC. If the computer can't lock them, the app won't save them.
- Your AI never sees a saved password. The app types it into the site for you, and your AI only learns whether the sign-in worked. A password that shows up on a page anyway is blanked out before your AI or the activity log gets it.
- Sign-ins don't sync unless you turn it on. If you do, each password is locked with a passphrase you make up before it leaves the computer. We never get the passphrase and can't read the passwords, or even see which sites they are for.
It asks before it sends, pays or deletes
Before your AI presses anything named like Send, Pay, Submit or Delete, or presses Enter in a message box, the app stops and asks you: Allow or Don't allow. The app's own assistant always asks, and that can't be switched off. The AI in the app's side panel asks too unless you turn that off, and for other AI tools you connect, the same question is on by default for new installs.
Every action that changes something goes through one checkpoint first: your rules are checked, a line is written to the activity log on your computer, and only then does it act. Rules like "Never touch my bank" or "Ask me before anything on this site" are written in plain words, and a "Never" rule always wins. If the rules file is ever damaged, the app refuses those actions rather than guessing.
Company rules can't be loosened by staff
A team owner can apply their rules to everyone on the team with one switch. The rules are signed on the owner's computer with a key that never leaves it. Each member's app checks that signature before using them, refuses an older copy, and only ever adds them on top of the member's own rules: stricter, never looser. A member can add rules of their own, but can't switch the owner's off.
Admins can see the team's rules but can't sign them. One key signs, so there's one thing to trust, and nobody, including us, can slip in a copy that loosens them.
Shared workflows are encrypted end to end
When someone shares a workflow with the team, their app locks it (AES-256-GCM) with a team key that only the team's computers hold. Each computer gets that key wrapped for it alone by another team computer. Our server stores and passes on locked copies and wrapped keys, and can't open either.
What our server can see: the team's name, who is on it and their role, each shared workflow's name, who shared it and when, and how many times each person ran it.
Sync between your own computers is encrypted end to end
What your Vassal has learned can follow you to your other computers. It's locked (AES-256-GCM) on your computer before it leaves, with a key only your computers hold. A new computer gets that key only when one of your other computers approves it, or with a recovery code you keep. We store the locked copy and can't open it. Website cookies and sessions never sync.
The team activity summary is counts only
On a team, each person's app sends the owner and admins a weekly summary: when they were last active, how many runs, which workflows ran (by name) and how many failed, how many times it asked before acting and how each was answered, how many actions a rule stopped, and the time it gave back. Members see this in their app, in one line under Settings, Team.
It never includes what was on a page, messages, sign-ins, web addresses, files, or anything a workflow wrote. Our server rebuilds every summary field by field and drops anything else, keeps the last 26 weeks, and deletes a person's summary when they leave the team.
Roles on a team
- Owner: billing, deleting the team, handing it over, making admins, the team's rules, and everything an admin does. There is always exactly one, and they can't be removed.
- Admin: invites and removes members, hands out licenses, sees the activity summary and the team's rules, and can stop sharing any workflow.
- Member: uses the app and shares their own workflows with the team.
Our server checks the role on every request, whatever a web page or an app says.
What vassalagent.com stores
- Your account
- Your email, and each signed-in computer's name, operating system and when it was last online
- Billing
- Handled by Stripe. We see your plan, payments and billing details, never your full card number
- Your team
- Its name, people, roles and invites (an invite link is stored only as a one-way fingerprint)
- Shared workflows
- Locked copies we can't open, plus each one's name and run counts
- Team rules
- The signed rules file, as the owner's app made it. It is signed, not encrypted, so we can read it but can't change it
- Activity summary
- Weekly counts and workflow names for team owners and admins
- Sync
- A locked copy of your Vassal that we can't open
- Workflow links
- A workflow you send as a link, locked with a key that lives only in the link itself, for 14 days
- Crash reports
- Only if you turn them on
It is kept with Supabase (our database and file storage) and Vercel (the website). The privacy policy lists everyone who handles any of it, and how to delete it.
Other safeguards
- The connection other AI apps use to drive the browser listens only on your own computer and needs a key the app keeps there.
- Websites you visit can't reach the app's own controls, and opening or uploading a private file (like your keys or the app's own data) asks you first.
- Release builds run only from their own package, check it hasn't been altered, and refuse the switches that would let another program inject code into them.
Reporting a vulnerability
Email team@vassalagent.com with what you found and how to reproduce it. A person reads every report, and we'll reply to tell you what we're doing about it. Please give us a reasonable chance to fix it before you share it publicly. Our contact is also in security.txt.
Questions
Can you see what my staff do in the app?
No. Their browsing, pages, messages, sign-ins and chats stay on their computers. If they are on your team, their app sends you (the owner) and your admins a weekly summary in counts: runs, workflow names, questions asked and answered, actions a rule stopped, failures and time back. We store that summary for you, and it never includes what was on a page.
Can a staff member switch off the company's rules?
No. Rules the owner applies to the team are signed on the owner's computer. Every member's app checks the signature and can only add rules on top, never loosen or remove them. A rule changed anywhere else, including on our server, fails the check and is ignored.
What happens when someone leaves the team?
Removing them takes effect at once: our server stops giving them anything, the wrapped team keys we held for their computers are deleted, and the next team computer that opens makes a new key. Anything shared after that is locked with a key they never get. Like any file someone has already opened, what their computer already had stays there.
Do you have SOC 2, ISO 27001 or HIPAA certification?
No. We don't hold those certifications, and Vassal Agent is not built for protected health information. If your business needs one of them, email team@vassalagent.com before you buy and we'll tell you honestly whether it fits.
Does it train an AI on my data?
We don't train any AI. Your AI runs on your own plan with your AI provider (Anthropic, OpenAI or Google), under that provider's terms and your account's settings.
Questions from your office?
Email team@vassalagent.com and a person answers, usually the same day. Or try it on one computer first: it's free for 14 days, and you can cancel any time.